©2026 VEVD

Embroidery by Rosie Brain Embroidery

Designed by Studio Algae

Privacy Statement for Vevd AS

Vevd AS processes personal data in connection with the operation of the website vevd.ai, sales and marketing, delivery of client engagements and general administration of the business. This statement explains what data we process, why we process it, how long we keep it and what rights you have.

Last updated: 11 August 2026

1. Data controller

Vevd AS is the data controller for the processing described in this statement.

Company Vevd AS
Organisation number 837 377 862
Address Tordenskiolds gate 2, 0160 Oslo, Norway
Email hi@vevd.ai
Contact Lars Kvinge, CEO

Vevd is not required to appoint a data protection officer and has not done so. Please direct any privacy questions to the address above.

2. Our two roles

We process personal data in two distinct roles.

As data controller. We determine the purposes and means of the processing ourselves. This applies to the website, sales and marketing, client administration, supplier management and recruitment. This statement covers that processing.

As data processor. In client engagements, such as workflow mapping, we process personal data on behalf of the client and on the client’s instructions. The client is then the data controller, and the processing is governed by a separate data processing agreement. The client’s own privacy statement applies to that data.

3. What data we process

3.1 Visitors to vevd.ai

We process technical data such as IP address, browser type, device, time of visit and pages viewed. The purpose is to deliver and secure the website and to understand how it is used.

Legal basis: legitimate interest in secure and stable operation, GDPR Article 6(1)(f). For cookies that are not strictly necessary, the basis is your consent. See section 4.

Retention: 12 months for server logs, then deletion.

3.2 Enquiries

When you contact us through the contact form, by email, by phone or on LinkedIn, we process your name, contact details, employer and the content of the enquiry.

Legal basis: legitimate interest in responding to enquiries, Article 6(1)(f), or steps taken prior to entering into a contract, Article 6(1)(b).

Retention: until the enquiry has been dealt with, normally no more than 12 months, unless it leads to a client relationship.

3.3 Sales and outbound marketing

We contact people in professional roles at organisations we believe may benefit from our services. We process name, job title, employer, publicly available profile information, business contact details and a log of contact and responses.

The data is collected from publicly available sources, including LinkedIn, company websites, the Norwegian Register of Business Enterprises and similar open registers.

Legal basis: legitimate interest in marketing our services to relevant organisations, Article 6(1)(f). We have assessed that this interest outweighs the impact on the individual, because the contact takes place in a professional context, concerns the organisation’s affairs rather than private matters, involves a limited set of data, does not involve special categories of personal data, and because opting out is straightforward.

You may object to this processing at any time, see section 9. We will then record an opt-out so that you are not contacted again.

Retention: up to 24 months after the last contact, or until you opt out. Opt-out records are kept for as long as necessary to honour them.

3.4 Clients and client contacts

We process name, job title, contact details, correspondence and data relating to the contract, delivery and invoicing.

Legal basis: performance of a contract, Article 6(1)(b), legitimate interest in client management, Article 6(1)(f), and legal obligation for accounting records, Article 6(1)(c).

Retention: for the duration of the client relationship and then up to 3 years. Accounting records are kept for five years after the end of the financial year in accordance with the Norwegian Bookkeeping Act.

3.5 Suppliers and partners

We process contact details for contact persons at suppliers and partners in order to manage the relationship.

Legal basis: performance of a contract and legitimate interest, Article 6(1)(b) and (f).

Retention: for the duration of the relationship and then up to 3 years.

3.6 Job applicants

We process applications, CVs, references and interview notes.

Legal basis: steps taken prior to entering into a contract, Article 6(1)(b). If we wish to keep an application on file for future openings, we ask for consent, Article 6(1)(a).

Retention: deleted once the recruitment process is closed, unless you consent to longer storage, normally up to 12 months.

3.7 Personal data in client engagements

When mapping workflows, we may encounter personal data in the client’s systems and processes, for example the names of employees performing tasks, approvers in an approval chain or the content of case handling.

We work on the principle of data minimisation. We record roles and functions rather than named individuals wherever possible, and we do not extract more data than the engagement requires. This processing is carried out on the client’s instructions and under a data processing agreement.

4. Cookies

The website is built in Framer. Framer’s built-in visitor statistics are cookie-free and set no persistent identifiers.

In addition, we use Google Analytics to measure use of the website. Google Analytics sets the following cookies:

Cookie Purpose Duration
_ga Distinguishes visitors 24 months
_ga_DNYP30EMXJ Maintains session state 24 months

You can delete or block cookies in your browser, and you can opt out of Google Analytics across all websites by installing Google’s browser opt-out add-on.

5. Who we share data with

We do not sell personal data. We share data with suppliers who process it on our behalf, and we have a data processing agreement with each of them.

Supplier Purpose Location
Framer Website hosting and operation EEA and USA
Google Analytics Website visitor statistics EEA and USA
Google Workspace Email, calendar and file storage EEA and USA
Google Cloud Firestore Database and client records EEA and USA
Tripletex Accounting and bookkeeping system EEA

We do not enter personal data from client engagements into AI tools.

We may also disclose data where we are legally required to do so, or to advisers where necessary, for example our auditor or legal counsel.

6. Transfers outside the EEA

Some of our suppliers process data outside the EEA, mainly in the United States. Transfers are based on the European Commission’s Standard Contractual Clauses, Article 46(2)(c), or certification under the EU-US Data Privacy Framework, together with supplementary measures where required. You may request a copy of the transfer safeguards by contacting us.

7. Security

We have technical and organisational measures in place to protect personal data, including access control on a need-to-know basis, two-factor authentication, encryption in transit and at rest, logging, use of suppliers with a documented security level, and procedures for handling incidents. In the event of a personal data breach, we notify the Norwegian Data Protection Authority within 72 hours where required, and the individuals concerned if the breach poses a high risk.

8. Automated decisions and use of AI

We use AI tools to support our analysis and mapping work. We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22. All assessments and recommendations are reviewed by a person at Vevd.

9. Your rights

You have the right to request access to the data we hold about you, to have inaccurate data corrected, to have data erased, to request restriction of processing, to receive data you have provided in a machine-readable format (data portability), to object to processing based on legitimate interest, including direct marketing, and to withdraw consent where processing is based on consent.

Requests should be sent to hi@vevd.ai. We normally respond within 30 days, free of charge. We may ask you to verify your identity where necessary to ensure that data is not disclosed to the wrong person.

10. Complaints

If you disagree with how we process personal data, we would appreciate hearing from you first. You always have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), Postboks 458 Sentrum, 0105 Oslo, postkasse@datatilsynet.no.

11. Changes

We may update this statement following changes to our services, systems or applicable law. The current version is always available at vevd.ai. Where material changes are made, we will notify those affected where practically possible.

This is a translation of the Norwegian version of our privacy statement. In the event of any discrepancy, the Norwegian version prevails.